Skip to main content
Tools Reference

Datto EDR Tools

Written By Christopher Scaminaci

Last updated 7 days ago

Datto EDR Tools

dattoedr_ · 96 tools · Free 61 · Pro 35 Endpoint detection and response, built as Infocyte HUNT - the product's own addresses still say infocyte.com, which is not a typo. The base address is your own instance on that domain; a datto.com address is refused. The credential is a single API token minted in the product UI, and it stops working one year after creation with no renewal path, so a 401 is often the ordinary end of a token's life. Paging is offset and limit carried inside a JSON filter parameter, capped at 1000 by the vendor. Forensic reads are scoped to a box - a rollup over 7, 30 or 90 days - and with no box id given the tenant's Global Last 7 days box is used. Most of the write surface reaches live customer machines: restoring an isolated host is treated as destructive, while creating or publishing a rule is not, because no code runs on an endpoint.

All connector tools · Datto EDR setup guide

Datto EDR tool groups

Platform

ToolPlanAccessSummary
dattoedr_count_recordsFreeRead-onlyCount the rows of any Datto EDR collection matching a filter, without fetching them.
dattoedr_get_boxFreeRead-onlyGet one aggregation box by id, from dattoedr_list_boxes.
dattoedr_get_jobFreeRead-onlyGet one platform job by id, from dattoedr_list_jobs.
dattoedr_get_taskFreeRead-onlyGet one task's status by id — the follow-up call for EVERY scan and containment action on this connector, because none of them returns its result.
dattoedr_get_user_activityFreeRead-onlyGet one audit log entry by id, from dattoedr_list_user_activities.
dattoedr_get_versionFreeRead-onlyGet the Datto EDR instance and API version.
dattoedr_list_boxesFreeRead-onlyList the aggregation boxes.
dattoedr_list_jobsFreeRead-onlyList Datto EDR's own background jobs — the platform's internal work, not the user tasks a scan or a containment action creates.
dattoedr_list_task_item_progressFreeRead-onlyList the progress messages beneath one task item — the running commentary for a single endpoint.
dattoedr_list_task_itemsFreeRead-onlyList a task's per-host items — one row per endpoint the task touched, with that endpoint's own outcome.
dattoedr_list_tasksFreeRead-onlyList user tasks.
dattoedr_list_user_activitiesFreeRead-onlyList the audit log — who did what in Datto EDR and when.
dattoedr_list_usersFreeRead-onlyList the users of this Datto EDR instance.

[Datto EDR] Count the rows of any Datto EDR collection matching a filter, without fetching them. Returns {"count": N}. USE THIS FIRST on the big forensic tables: Datto EDR warns that wide, unfiltered queries strain its database, and a count tells you whether a filter is narrow enough before you ask for the rows. Valid collections are the ones the other tools read — Alerts, Agents, ScanProcessInstances, ScanHosts and so on; the error message lists them all if you pass one that is not recognized. This count is NOT scoped to an aggregation box: the forensic tools fall back to your Global Last 7 Days box when you give them no box id, so a count of a forensic table can be far larger than what those tools return. Put the same boxId in this filter to compare like with like.

ParamTypeRequiredDefaultDescription
collectionstringyesThe collection to count, for example Alerts, Agents, ScanProcessInstances or ScanHosts. Case-insensitive. An unrecognized name is refused with the full list of valid values.
wherestringnonullFilter as a JSON object in Datto EDR's LoopBack where syntax, for example {"threatWeight":{"gt":5}}. Omit to count the whole collection.

[Datto EDR] Get one aggregation box by id, from dattoedr_list_boxes. Returns the box's scope and window along with its summary counters.

ParamTypeRequiredDefaultDescription
boxIdstringyesThe box id, from dattoedr_list_boxes. A GUID.
ParamTypeRequiredDefaultDescription
jobIdstringyesThe job id, from dattoedr_list_jobs. A GUID.

[Datto EDR] Get one task's status by id — the follow-up call for EVERY scan and containment action on this connector, because none of them returns its result. Status is created, active, completed, cancelled or failed, alongside a percentage and elapsed seconds. For per-host detail use dattoedr_list_task_items, and for the messages beneath each host use dattoedr_list_task_item_progress. Once the task completes, the findings themselves are in dattoedr_list_scan_hosts, dattoedr_list_extension_details and dattoedr_list_alerts, keyed by the scan id.

ParamTypeRequiredDefaultDescription
taskIdstringyesThe task id, returned by any scan or response tool. A GUID.
ParamTypeRequiredDefaultDescription
activityIdstringyesThe audit entry id, from dattoedr_list_user_activities. A GUID.

[Datto EDR] Get the Datto EDR instance and API version. The cheapest call on the connector — use it to confirm the instance address and token are working before running anything expensive.

[Datto EDR] List the aggregation boxes. A box is a pre-computed rollup of results over one scope and one window — Global or a single target group, across 7, 30 or 90 days — and its id is what scopes most forensic and object reads. START HERE before using the forensic tools: pass the box id you want to dattoedr_list_process_instances and its siblings, or they fall back to the Global Last 7 Days box and the result silently means 'the last week'.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000. Omit for the API default.
orderstringnonullSort expression, for example 'name ASC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"targetId":null} for the Global boxes.

[Datto EDR] List Datto EDR's own background jobs — the platform's internal work, not the user tasks a scan or a containment action creates. For those use dattoedr_list_tasks.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'createdOn DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

[Datto EDR] List the progress messages beneath one task item — the running commentary for a single endpoint. The deepest level of the task chain; use it when a host is stuck or failed and the item's own status does not say why. Filter on taskItemId, from dattoedr_list_task_items.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'createdOn ASC' to read the messages in order.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax. Scope this to one item with {"taskItemId":"<item id>"}.

[Datto EDR] List a task's per-host items — one row per endpoint the task touched, with that endpoint's own outcome. Filter on userTaskId to scope it to one task, or the whole table comes back.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'createdOn DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax. Scope this to one task with {"userTaskId":"<task id>"} — without it every task's items are returned.

[Datto EDR] List user tasks. Every scan, network enumeration, containment action and offline import on this connector creates one, so this is where to look for work that is running or recently finished. Filter on type to separate scans from response actions.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'createdOn DESC' for the most recent work first.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"status":"Active"}.

[Datto EDR] List the audit log — who did what in Datto EDR and when. Use it to evidence a containment action for a client, or to answer 'who isolated that machine'.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'createdOn DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"userId":"<user id>"}.

[Datto EDR] List the users of this Datto EDR instance. Most objects carry a createdBy or updatedBy id rather than a name — this is how those ids become people. Note that a Datto EDR API token inherits the rights of the user who created it, so this list is also what decides how far any token can reach.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. Datto EDR's maximum is 1000; values above it are clamped. Omit for the API default.
orderstringnonullSort expression, for example 'createdOn DESC'. Omit for the API default.
skipintegernonullRecords to skip before the first returned row. Datto EDR pages by offset, not by page number — for the second page of 100, pass skip=100.
wherestringnonullFilter as a JSON object in Datto EDR's LoopBack where syntax, for example {"email":{"ilike":"%contoso.com"}}. Supported operators include ilike, regexp, and, or, nin, gt and lt.

Alerts

ToolPlanAccessSummary
dattoedr_get_alertFreeRead-onlyGet one alert by id, from dattoedr_list_alerts.
dattoedr_get_reportFreeRead-onlyGet one report's metadata by id, from dattoedr_list_reports.
dattoedr_list_alertsFreeRead-onlyList alerts raised in the LAST 30 DAYS — threat name and weight, the host and file involved, and whether Datto EDR judged it malicious.
dattoedr_list_archived_alertsFreeRead-onlyList alerts OLDER than 30 days.
dattoedr_list_reportsFreeRead-onlyList the reports Datto EDR has generated, with their type, scope and generation time.

[Datto EDR] Get one alert by id, from dattoedr_list_alerts. Returns the full detection record. To pull the forensic evidence behind it, take the scan id from the alert and pass it to the forensic tools such as dattoedr_list_process_instances.

ParamTypeRequiredDefaultDescription
alertIdstringyesThe alert id, from dattoedr_list_alerts. A GUID.

[Datto EDR] Get one report's metadata by id, from dattoedr_list_reports. The report file itself is not available through this API.

ParamTypeRequiredDefaultDescription
reportIdstringyesThe report id, from dattoedr_list_reports. A GUID.

[Datto EDR] List alerts raised in the LAST 30 DAYS — threat name and weight, the host and file involved, and whether Datto EDR judged it malicious. This is the connector's main read and the natural starting point for a morning triage sweep or ticket enrichment. IMPORTANT: alerts older than 30 days are NOT here — Datto EDR moves them to a separate archive, so use dattoedr_list_archived_alerts for anything beyond a month. Alerts come from four sources (rule, reputation, compliance and extension); filter on sourceType to separate them.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. Datto EDR's maximum is 1000; values above it are clamped. Omit for the API default.
orderstringnonullSort expression, for example 'createdOn DESC' for the newest alerts first.
skipintegernonullRecords to skip before the first returned row. Datto EDR pages by offset, not by page number.
wherestringnonullFilter as a JSON object in Datto EDR's LoopBack where syntax, for example {"threatWeight":{"gt":5}} or {"sourceType":"rule"}. Narrow this wherever you can — Datto EDR warns that wide queries strain its database.

[Datto EDR] List alerts OLDER than 30 days. Datto EDR keeps only the last 30 days in its live alert table and moves everything before that here, so this is the tool for a quarterly review, an annual report, or any question about a period further back than a month. Use dattoedr_list_alerts for the current month, and read both when a window straddles the 30-day boundary.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'createdOn DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax. A date window is the usual filter here, for example {"createdOn":{"between":["2026-01-01","2026-03-31"]}}.

[Datto EDR] List the reports Datto EDR has generated, with their type, scope and generation time. Returns report METADATA — the report files themselves are downloaded from the Datto EDR interface, not through this API.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'createdOn DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

Endpoints & Estate

ToolPlanAccessSummary
dattoedr_create_controller_groupProWriteCreate a controller group.
dattoedr_create_discovery_queryProWriteCreate an agentless discovery query — an IP range, hostname pattern, LDAP query or AWS query defining where to look for machines.
dattoedr_create_target_groupProWriteCreate a target group.
dattoedr_delete_addressProDestructiveDelete one discovered address and its history.
dattoedr_delete_addressesProDestructiveDelete SEVERAL discovered addresses at once, by id.
dattoedr_delete_archived_target_groupProDestructivePermanently delete an ARCHIVED target group — one already removed from active use but still held for its history.
dattoedr_delete_controller_groupProDestructiveDelete a controller group.
dattoedr_delete_discovery_queryProDestructiveDelete a discovery query.
dattoedr_delete_target_groupProDestructiveDelete a target group.
dattoedr_get_agentFreeRead-onlyGet one agent by id, from dattoedr_list_agents.
dattoedr_list_addressesFreeRead-onlyList the addresses discovery has found in a target group, with whether each one is reachable and when it was last accessed.
dattoedr_list_agentsFreeRead-onlyList the installed Datto EDR agents, with each machine's hostname, operating system, version and last check-in.
dattoedr_list_controller_groupsFreeRead-onlyList controller groups — the collectors that reach a customer's network on Datto EDR's behalf.
dattoedr_list_discovery_queriesFreeRead-onlyList the agentless discovery queries defined on this instance — IP range, hostname, LDAP and AWS queries that find machines to scan.
dattoedr_list_target_groupsFreeRead-onlyList target groups — the logical groupings of hosts Datto EDR scans and reports against.
dattoedr_uninstall_agentProDestructiveREMOVE the Datto EDR agent from one or more live endpoints.

[Datto EDR] Create a controller group. Additive — it defines the grouping and reaches no endpoint.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object, for example {"name":"Contoso Collectors"}.

[Datto EDR] Create an agentless discovery query — an IP range, hostname pattern, LDAP query or AWS query defining where to look for machines. This only DEFINES the query; it does not run it and touches nothing on the network until an enumeration is dispatched with dattoedr_enumerate_target_group.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object describing the query, for example {"targetId":"<target group id>","value":"10.1.0.0/24","type":"IP"}.

[Datto EDR] Create a target group. Purely additive — it defines an empty grouping and touches no endpoint. Nothing is scanned until a scan is dispatched against it.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object, for example {"name":"Contoso Servers"}.

[Datto EDR] Delete one discovered address and its history. Irreversible; the address reappears only if discovery finds it again.

ParamTypeRequiredDefaultDescription
addressIdstringyesThe address id, from dattoedr_list_addresses. A GUID.

[Datto EDR] Delete SEVERAL discovered addresses at once, by id. Bulk and irreversible — the discovery history for each address goes with it. List what you are about to remove with dattoedr_list_addresses first. To delete a single address use dattoedr_delete_address instead.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object naming the addresses to delete, for example {"ids":["<address id>","<address id>"]}. Ids come from dattoedr_list_addresses.

[Datto EDR] Permanently delete an ARCHIVED target group — one already removed from active use but still held for its history. This is the second and final deletion; the historical data goes with it.

ParamTypeRequiredDefaultDescription
archivedTargetGroupIdstringyesThe archived target group id. A GUID.

[Datto EDR] Delete a controller group. Any agentless scanning that depended on those collectors stops working.

ParamTypeRequiredDefaultDescription
controllerGroupIdstringyesThe controller group id, from dattoedr_list_controller_groups. A GUID.

[Datto EDR] Delete a discovery query. Future enumerations of its target group will no longer look where it looked, so machines it used to find stop being discovered.

ParamTypeRequiredDefaultDescription
queryIdstringyesThe query id, from dattoedr_list_discovery_queries. A GUID.

[Datto EDR] Delete a target group. This CASCADES: the group's discovered addresses and the scan data held against it go with it. Check what the group contains with dattoedr_list_addresses before deleting.

ParamTypeRequiredDefaultDescription
targetGroupIdstringyesThe target group id, from dattoedr_list_target_groups. A GUID.

[Datto EDR] Get one agent by id, from dattoedr_list_agents. Returns the machine's full agent record.

ParamTypeRequiredDefaultDescription
agentIdstringyesThe agent id, from dattoedr_list_agents. A GUID.

[Datto EDR] List the addresses discovery has found in a target group, with whether each one is reachable and when it was last accessed. This is the agentless counterpart to dattoedr_list_agents — machines Datto EDR knows about but does not necessarily have an agent on.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'lastAccessedOn DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax. Scope to one group with {"targetId":"<target group id>"}, or find reachable hosts with {"accessible":true}.

[Datto EDR] List the installed Datto EDR agents, with each machine's hostname, operating system, version and last check-in. THE reconciliation read: this is how you answer 'is every endpoint I bill for actually protected and reporting in'. Filter on the authorized and active flags to separate machines that are enrolled from machines that are alive.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. Datto EDR's maximum is 1000; values above it are clamped.
orderstringnonullSort expression, for example 'lastAccessedOn DESC' to find stale agents.
skipintegernonullRecords to skip before the first returned row. Datto EDR pages by offset, not by page number.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"active":false} for agents that have stopped checking in.
ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'name ASC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

[Datto EDR] List the agentless discovery queries defined on this instance — IP range, hostname, LDAP and AWS queries that find machines to scan. Listing them is read-only; a query only reaches the network when an enumeration is dispatched against its target group.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'name ASC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"targetId":"<target group id>"}.

[Datto EDR] List target groups — the logical groupings of hosts Datto EDR scans and reports against. A target group id is what scopes a group scan, a network enumeration and most aggregation boxes, so this is usually the first call before dispatching any scan.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'name ASC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"name":"OnDemand"}.

[Datto EDR] REMOVE the Datto EDR agent from one or more live endpoints. The machines lose detection and response coverage immediately and stay unprotected until someone reinstalls the agent by hand. There is no undo and no test mode. Confirm which machines are in scope before running this — pass agent ids from dattoedr_list_agents rather than a broad selector.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object naming the endpoints to uninstall, for example {"agentIds":["<agent id>"]}. Agent ids come from dattoedr_list_agents.

Scan Credentials

ToolPlanAccessSummary
dattoedr_create_scan_credentialProDestructiveStore a new scan credential in Datto EDR.
dattoedr_delete_scan_credentialProDestructiveDelete a stored scan credential.
dattoedr_list_scan_credentialsFreeRead-onlyList the credentials Datto EDR holds for agentless scanning — their names, types and where they are used.

[Datto EDR] Store a new scan credential in Datto EDR. The request body carries a REAL, WORKING domain or SSH credential — this writes a live secret into the platform, and anything that can dispatch a scan can then use it against the customer's machines. Marked destructive for that reason rather than for its verb. Prefer entering credentials in the Datto EDR interface, where the secret never travels through a tool call.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object describing the credential, for example {"name":"Contoso domain scan","username":"…","password":"…"}. Contains a live secret.

[Datto EDR] Delete a stored scan credential. Any agentless scan or schedule that relied on it begins failing, and the secret cannot be recovered — it has to be re-entered.

ParamTypeRequiredDefaultDescription
credentialIdstringyesThe credential id, from dattoedr_list_scan_credentials. A GUID.

[Datto EDR] List the credentials Datto EDR holds for agentless scanning — their names, types and where they are used. METADATA ONLY: the passwords and keys themselves are never returned by this API.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'name ASC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

Scans & Scheduling

ToolPlanAccessSummary
dattoedr_create_scan_recordProWriteCreate an empty scan record to hold the results of an offline survey import.
dattoedr_create_scheduled_jobProDestructiveCreate a RECURRING scan on a cron schedule.
dattoedr_delete_scheduled_jobProDestructiveDelete a scheduled scan.
dattoedr_enumerate_target_groupProDestructiveRun network discovery for a target group — an ACTIVE SWEEP of the customer's own infrastructure using that group's discovery queries.
dattoedr_get_scanFreeRead-onlyGet one scan by id, from dattoedr_list_scans.
dattoedr_list_scansFreeRead-onlyList scans, with each one's target group, timing and result counts.
dattoedr_list_scheduled_jobsFreeRead-onlyList the scheduled scans on this instance, with each one's cron expression, target group and scan options.
dattoedr_scan_targetProDestructiveLaunch a forensic scan of a SINGLE endpoint by hostname or IP address.
dattoedr_scan_target_groupProDestructiveLaunch a forensic scan of an ENTIRE target group — every endpoint in it, right now.

[Datto EDR] Create an empty scan record to hold the results of an offline survey import. Reaches no endpoint and scans nothing — it only creates the container. NOTE: this operation is the one path in the Datto EDR connector that StackJack has not seen the vendor's own client call, so its address is inferred from the model name rather than observed. Treat a 404 here as 'this path may be wrong' rather than 'the record does not exist', and report it.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object describing the scan record, for example {"targetId":"<target group id>"}.

[Datto EDR] Create a RECURRING scan on a cron schedule. Marked destructive because the effect is live dispatch, just deferred: from now on this scan reaches every endpoint in the target group on every run, without anyone approving it again. Check the existing schedule with dattoedr_list_scheduled_jobs first, and prefer off-hours cron expressions on production networks.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object, for example {"name":"Weekly sweep","targetId":"<target group id>","cronExpression":"0 2 * * 0"}.

[Datto EDR] Delete a scheduled scan. The recurring sweep stops, so the target group is no longer scanned on that cadence until something replaces it — check with the customer before removing a schedule that underpins their coverage commitments.

ParamTypeRequiredDefaultDescription
scheduledJobIdstringyesThe scheduled scan id, from dattoedr_list_scheduled_jobs. A GUID.

[Datto EDR] Run network discovery for a target group — an ACTIVE SWEEP of the customer's own infrastructure using that group's discovery queries. It generates real network traffic and can trip intrusion-detection systems, so agree the window with the customer before running it against a production network. Returns a task id; follow it with dattoedr_get_task, then read what it found with dattoedr_list_addresses.

ParamTypeRequiredDefaultDescription
bodystringnonullOptional request body as a JSON object. Omit for a default enumeration using the group's existing discovery queries.
targetGroupIdstringyesThe target group id to enumerate, from dattoedr_list_target_groups. A GUID.

[Datto EDR] Get one scan by id, from dattoedr_list_scans. Returns the scan's own record — what was scanned, when, and the totals it produced.

ParamTypeRequiredDefaultDescription
scanIdstringyesThe scan id, from dattoedr_list_scans. A GUID.

[Datto EDR] List scans, with each one's target group, timing and result counts. A scan id from here is the key into the forensic tables — pass it in the where filter of dattoedr_list_scan_hosts, dattoedr_list_process_instances and their siblings to see what that scan found.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. Datto EDR's maximum is 1000; values above it are clamped.
orderstringnonullSort expression, for example 'createdOn DESC' for the most recent scans first.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"targetId":"<target group id>"}.

[Datto EDR] List the scheduled scans on this instance, with each one's cron expression, target group and scan options. Read this before adding a schedule — overlapping recurring scans of the same group are a common cause of unexplained load on a customer's machines.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'name ASC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

[Datto EDR] Launch a forensic scan of a SINGLE endpoint by hostname or IP address. Live dispatch: the machine begins collecting processes, modules, drivers, autostarts, accounts and network connections immediately. The target must have an active agent, or an accessible address entry in the target group. Returns a task id — follow it with dattoedr_get_task. This is the read-only investigative counterpart to the containment tools; it collects evidence and changes nothing on the machine.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object. At minimum {"target":"HOSTNAME-OR-IP","targetGroup":{"id":"<target group id>"}}; add an options object to narrow what is collected.

[Datto EDR] Launch a forensic scan of an ENTIRE target group — every endpoint in it, right now. This is live dispatch: agents begin collecting, agentless hosts are reached over the network, and a large group means real load on the customer's machines. Scope it first with dattoedr_list_target_groups and dattoedr_list_addresses. Returns a task id, not results: follow it with dattoedr_get_task, then read the findings from dattoedr_list_scan_hosts and dattoedr_list_alerts. To scan a single machine use dattoedr_scan_target instead.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object. Pass for a default full collection, or narrow the sweep with scan options and a where clause, for example {"options":{"process":true,"module":false},"where":{"accessible":true}}.
targetGroupIdstringyesThe target group id to scan, from dattoedr_list_target_groups. A GUID.

Response Actions

ToolPlanAccessSummary
dattoedr_collect_evidenceProDestructiveCollect forensic evidence from an endpoint — data files, event logs and related artifacts — and copy it to the storage bucket configured in Datto EDR.
dattoedr_isolate_hostProDestructiveISOLATE an endpoint — cut it off the network so it can reach only Datto EDR and other security tools.
dattoedr_kill_processProDestructiveTERMINATE a process on a live endpoint, selected by name, SHA1 hash, process id or image path.
dattoedr_recover_filesProDestructiveCopy named files off an endpoint to the recovery point configured in Datto EDR (an S3 bucket, FTP server or file share).
dattoedr_restore_hostProDestructiveRESTORE an isolated endpoint to the network.
dattoedr_run_extensionProDestructiveRun ANY named extension on a live endpoint.

[Datto EDR] Collect forensic evidence from an endpoint — data files, event logs and related artifacts — and copy it to the storage bucket configured in Datto EDR. This MOVES CUSTOMER DATA OFF THE MACHINE to a third-party location, so check the destination and the customer's data-handling agreement before running it. The extension name is required rather than assumed: StackJack has no vendor source naming the evidence-collection extension, so pass the exact name from your instance's extension list (see dattoedr_list_extensions). Returns a task id.

ParamTypeRequiredDefaultDescription
extensionArgsstringnonullOptional extension arguments as a JSON object, for example a narrower collection scope. Omit to use the extension's own defaults.
extensionNamestringyesExact name of the evidence-collection extension as it appears in your Datto EDR instance. Find it with dattoedr_list_extensions. Required — there is no reliable default for this action.
targetstringyesHostname or IP address of the endpoint.
targetGroupIdstringnonullTarget group the action runs under. Omit to use the group named OnDemand.

[Datto EDR] ISOLATE an endpoint — cut it off the network so it can reach only Datto EDR and other security tools. The machine stops serving users, stops reaching file shares, line-of-business applications and the internet, and stays that way until someone restores it with dattoedr_restore_host. Isolating a domain controller, a hypervisor or a shared server takes a customer's service down. Confirm the exact hostname before running this, and be sure it is the machine you mean. Returns a task id; follow it with dattoedr_get_task.

ParamTypeRequiredDefaultDescription
targetstringyesHostname or IP address of the endpoint to isolate. Must have an active agent or an accessible address entry.
targetGroupIdstringnonullTarget group the action runs under. Omit to use the group named OnDemand — the tool fails clearly if that group does not exist rather than creating one.

[Datto EDR] TERMINATE a process on a live endpoint, selected by name, SHA1 hash, process id or image path. The process stops immediately, with no save and no warning to the user at the keyboard — killing the wrong one loses work or takes a service down. Prefer the SHA1 or the full path over a bare name, because a name can match several processes. Returns a task id; follow it with dattoedr_get_task, and confirm the outcome with dattoedr_list_extension_details.

ParamTypeRequiredDefaultDescription
processSelectorstringyesSelector for the process to kill, as a JSON object. Supply at least one of processName, sha1, processId or processPath — for example {"sha1":"da39a3ee5e6b4b0d3255bfef95601890afd80709"} or {"processPath":"C:\Windows\Temp\bad.exe"}. A bare processName can match more than one running process.
targetstringyesHostname or IP address of the endpoint.
targetGroupIdstringnonullTarget group the action runs under. Omit to use the group named OnDemand.

[Datto EDR] Copy named files off an endpoint to the recovery point configured in Datto EDR (an S3 bucket, FTP server or file share). This MOVES CUSTOMER DATA to that destination, and the files may be malicious or may contain sensitive content — check the destination and the customer's agreement first. The extension name is required rather than assumed: StackJack has no vendor source naming the file-recovery extension, so pass the exact name from dattoedr_list_extensions. Returns a task id.

ParamTypeRequiredDefaultDescription
extensionArgsstringyesExtension arguments as a JSON object naming the files to recover, for example {"paths":["C:\Windows\Temp\suspect.exe"]}.
extensionNamestringyesExact name of the file-recovery extension as it appears in your Datto EDR instance. Find it with dattoedr_list_extensions. Required — there is no reliable default for this action.
targetstringyesHostname or IP address of the endpoint.
targetGroupIdstringnonullTarget group the action runs under. Omit to use the group named OnDemand.

[Datto EDR] RESTORE an isolated endpoint to the network. Marked destructive even though it undoes an isolation: putting a machine back on the network during a live incident re-exposes everything it can reach, so it needs the same deliberate approval as isolating it. Confirm the machine is actually clean before running this. Returns a task id; follow it with dattoedr_get_task.

ParamTypeRequiredDefaultDescription
targetstringyesHostname or IP address of the isolated endpoint to restore.
targetGroupIdstringnonullTarget group the action runs under. Omit to use the group named OnDemand.

[Datto EDR] Run ANY named extension on a live endpoint. An extension is a script Datto EDR executes on the machine, so this is an open-ended remote execution verb: what it does depends entirely on the extension, and it can do anything the extension's author wrote. Use the specific tools instead where one exists — dattoedr_isolate_host, dattoedr_restore_host, dattoedr_kill_process — and reach for this one only for extensions with no dedicated tool. Read the extension first with dattoedr_get_extension_latest_version so you know what you are running. Returns a task id; the output lands in dattoedr_list_extension_details.

ParamTypeRequiredDefaultDescription
extensionArgsstringnonullOptional extension arguments as a JSON object. Omit to use the extension's own defaults.
extensionNamestringyesExact name of the extension to run, as it appears in your Datto EDR instance. Find it with dattoedr_list_extensions.
targetstringyesHostname or IP address of the endpoint.
targetGroupIdstringnonullTarget group the action runs under. Omit to use the group named OnDemand.

Forensic Results

ToolPlanAccessSummary
dattoedr_get_extension_detailFreeRead-onlyRead a single extension execution result.
dattoedr_list_account_instancesFreeRead-onlyList the local and domain accounts a scan found on the machines it examined.
dattoedr_list_account_instances_by_hostFreeRead-onlyList account findings rolled up per machine — the same data as dattoedr_list_account_instances, grouped by host.
dattoedr_list_application_instancesFreeRead-onlyList the installed applications a scan found across the estate.
dattoedr_list_artifact_instancesFreeRead-onlyList the forensic artifacts a scan collected — the traces left behind by activity on the machine, rather than the running code itself.
dattoedr_list_autostart_instancesFreeRead-onlyList the autostart and persistence entries a scan found — scheduled tasks, services, run keys and the rest of the ways code arranges to run again after a reboot.
dattoedr_list_box_extension_instancesFreeRead-onlyList extension executions already aggregated across a box's whole window.
dattoedr_list_connection_instancesFreeRead-onlyList the network connections a scan observed, with the process at each end.
dattoedr_list_driver_instancesFreeRead-onlyList the kernel drivers a scan found loaded.
dattoedr_list_extension_detailsFreeRead-onlyList extension execution results WITH THEIR OUTPUT — success flag, threat verdict and the messages the extension wrote.
dattoedr_list_extension_instancesFreeRead-onlyList extension executions — which extension ran, on which machine, and whether it succeeded.
dattoedr_list_memory_scan_instancesFreeRead-onlyList what Datto EDR's memory scan found.
dattoedr_list_module_instancesFreeRead-onlyList the modules and libraries loaded into processes during a scan.
dattoedr_list_process_instancesFreeRead-onlyList the processes a scan found running, with each one's image path, hash and threat verdict.
dattoedr_list_scan_hostsFreeRead-onlyList the per-host results of scans — one row per machine, with its operating system, IP, the threat verdict Datto EDR reached and the totals it collected.
dattoedr_list_script_instancesFreeRead-onlyList the scripts a scan found on the machines it examined.

[Datto EDR] Read a single extension execution result. Datto EDR serves this from a separate single-record view alongside the list view, and the two are genuinely different endpoints rather than duplicates. Use dattoedr_list_extension_details when you want several results and this when you want exactly one; narrow it with the where filter.

ParamTypeRequiredDefaultDescription
boxIdstringnonullAggregation box to read from, from dattoedr_list_boxes. Omit and StackJack targets your Global Last 7 Days box (resolved once, then cached); pass a box id here to read a different rollup.
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'completedOn DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax identifying the single result you want, for example {"id":"<result id>"}.

[Datto EDR] List the local and domain accounts a scan found on the machines it examined. Use it to spot an account an attacker created, or a local administrator nobody knew about. For the same data grouped by machine use dattoedr_list_account_instances_by_host.

ParamTypeRequiredDefaultDescription
boxIdstringnonullAggregation box to read from, from dattoedr_list_boxes. Omit and StackJack targets your Global Last 7 Days box (resolved once, then cached); pass a box id here to read a different rollup.
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'name ASC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

[Datto EDR] List account findings rolled up per machine — the same data as dattoedr_list_account_instances, grouped by host. Use this one when the question is 'which machines does this account exist on', and the ungrouped one when the question is about the accounts themselves.

ParamTypeRequiredDefaultDescription
boxIdstringnonullAggregation box to read from, from dattoedr_list_boxes. Omit and StackJack targets your Global Last 7 Days box (resolved once, then cached); pass a box id here to read a different rollup.
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'hostname ASC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

[Datto EDR] List the installed applications a scan found across the estate. Doubles as a software inventory, and pairs with dattoedr_list_application_advisories to turn 'what is installed' into 'what is installed and vulnerable'.

ParamTypeRequiredDefaultDescription
boxIdstringnonullAggregation box to read from, from dattoedr_list_boxes. Omit and StackJack targets your Global Last 7 Days box (resolved once, then cached); pass a box id here to read a different rollup.
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'name ASC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"name":{"ilike":"%java%"}}.

[Datto EDR] List the forensic artifacts a scan collected — the traces left behind by activity on the machine, rather than the running code itself. Useful for reconstructing what happened after the fact.

ParamTypeRequiredDefaultDescription
boxIdstringnonullAggregation box to read from, from dattoedr_list_boxes. Omit and StackJack targets your Global Last 7 Days box (resolved once, then cached); pass a box id here to read a different rollup.
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'threatWeight DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

[Datto EDR] List the autostart and persistence entries a scan found — scheduled tasks, services, run keys and the rest of the ways code arranges to run again after a reboot. This is where you confirm an attacker established persistence, and what you check before declaring a machine clean.

ParamTypeRequiredDefaultDescription
boxIdstringnonullAggregation box to read from, from dattoedr_list_boxes. Omit and StackJack targets your Global Last 7 Days box (resolved once, then cached); pass a box id here to read a different rollup.
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'threatWeight DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

[Datto EDR] List extension executions already aggregated across a box's whole window. Cheaper than paging dattoedr_list_extension_instances when the question is about a period rather than a single scan — for example 'how many times did we isolate a host this month'.

ParamTypeRequiredDefaultDescription
boxIdstringnonullAggregation box to read from, from dattoedr_list_boxes. Omit and StackJack targets your Global Last 7 Days box (resolved once, then cached); pass a box id here to read a different rollup. On this tool especially, the box IS the question.
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'completedOn DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

[Datto EDR] List the network connections a scan observed, with the process at each end. Use it to find command-and-control traffic, and to work out which other machines a compromised host was talking to.

ParamTypeRequiredDefaultDescription
boxIdstringnonullAggregation box to read from, from dattoedr_list_boxes. Omit and StackJack targets your Global Last 7 Days box (resolved once, then cached); pass a box id here to read a different rollup.
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'threatWeight DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example a remote address you already suspect.

[Datto EDR] List the kernel drivers a scan found loaded. A malicious driver runs below most defenses, so an unrecognized or unsigned entry here is worth escalating even when everything else looks clean.

ParamTypeRequiredDefaultDescription
boxIdstringnonullAggregation box to read from, from dattoedr_list_boxes. Omit and StackJack targets your Global Last 7 Days box (resolved once, then cached); pass a box id here to read a different rollup.
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'threatWeight DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

[Datto EDR] List extension execution results WITH THEIR OUTPUT — success flag, threat verdict and the messages the extension wrote. This is how you confirm a containment action actually worked: after dattoedr_isolate_host or dattoedr_kill_process completes, filter here on the scan id from the task to read what the endpoint reported back.

ParamTypeRequiredDefaultDescription
boxIdstringnonullAggregation box to read from, from dattoedr_list_boxes. Omit and StackJack targets your Global Last 7 Days box (resolved once, then cached); pass a box id here to read a different rollup.
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'completedOn DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"scanId":"<scan id from the task>"}.

[Datto EDR] List extension executions — which extension ran, on which machine, and whether it succeeded. This is the summary of every containment action and custom script run; for the output each one produced use dattoedr_list_extension_details.

ParamTypeRequiredDefaultDescription
boxIdstringnonullAggregation box to read from, from dattoedr_list_boxes. Omit and StackJack targets your Global Last 7 Days box (resolved once, then cached); pass a box id here to read a different rollup.
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'completedOn DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"scanId":"<scan id>"}.

[Datto EDR] List what Datto EDR's memory scan found. This is where fileless and in-memory-only threats appear — malware that leaves nothing on disk shows up here and nowhere else.

ParamTypeRequiredDefaultDescription
boxIdstringnonullAggregation box to read from, from dattoedr_list_boxes. Omit and StackJack targets your Global Last 7 Days box (resolved once, then cached); pass a box id here to read a different rollup.
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'threatWeight DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

[Datto EDR] List the modules and libraries loaded into processes during a scan. Use it to find code injected into a legitimate process — the parent process looks clean in dattoedr_list_process_instances, and the malicious payload is here.

ParamTypeRequiredDefaultDescription
boxIdstringnonullAggregation box to read from, from dattoedr_list_boxes. Omit and StackJack targets your Global Last 7 Days box (resolved once, then cached); pass a box id here to read a different rollup.
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'threatWeight DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax. This table is large — always narrow it.

[Datto EDR] List the processes a scan found running, with each one's image path, hash and threat verdict. The first table to read during an incident: it is where a malicious executable shows up. Filter on scanId or hostname, and on threatStatus to see only what Datto EDR flagged.

ParamTypeRequiredDefaultDescription
boxIdstringnonullAggregation box to read from, from dattoedr_list_boxes. Omit and StackJack targets your Global Last 7 Days box (resolved once, then cached); pass a box id here to read a different rollup.
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'threatWeight DESC' to surface the worst first.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"threatStatus":"Bad"}. This table is large — always narrow it.

[Datto EDR] List the per-host results of scans — one row per machine, with its operating system, IP, the threat verdict Datto EDR reached and the totals it collected. START HERE when reading scan results: this is the summary, and the other forensic tools are the detail beneath it. Filter on scanId to scope to one scan.

ParamTypeRequiredDefaultDescription
boxIdstringnonullAggregation box to read from, from dattoedr_list_boxes. Omit and StackJack targets your Global Last 7 Days box (resolved once, then cached); pass a box id here to read a different rollup.
limitintegernonullMaximum records to return. Datto EDR's maximum is 1000; values above it are clamped.
orderstringnonullSort expression, for example 'completedOn DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"scanId":"<scan id>"} or {"threatStatus":"Bad"}.

[Datto EDR] List the scripts a scan found on the machines it examined. PowerShell, batch and shell scripts are a common attacker foothold, and one dropped somewhere unusual is worth reading in full.

ParamTypeRequiredDefaultDescription
boxIdstringnonullAggregation box to read from, from dattoedr_list_boxes. Omit and StackJack targets your Global Last 7 Days box (resolved once, then cached); pass a box id here to read a different rollup.
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'threatWeight DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

Threat Intelligence & Triage

ToolPlanAccessSummary
dattoedr_add_commentProWriteAdd a note to an object in Datto EDR.
dattoedr_create_flagProWriteCreate a triage flag.
dattoedr_delete_flagProDestructiveDelete a triage flag.
dattoedr_get_file_dwell_timeFreeRead-onlyGet one dwell-time record by its own id, from dattoedr_list_file_dwell_times.
dattoedr_get_file_reputationFreeRead-onlyLook up a file's reputation by its SHA1 hash — Datto EDR's verdict on whether that exact binary is known good, unknown or malicious.
dattoedr_get_flagFreeRead-onlyGet one triage flag by id, from dattoedr_list_flags.
dattoedr_list_commentsFreeRead-onlyList the notes analysts have left on objects — the running commentary on an investigation.
dattoedr_list_file_dwell_timesFreeRead-onlyList how long files have been present in the estate — first seen, last seen, and on how many machines.
dattoedr_list_flagsFreeRead-onlyList the triage flags defined on this instance — the colored labels analysts apply to findings, each with a weight that influences how Datto EDR scores them.
dattoedr_replace_flagProDestructiveREPLACE a triage flag wholesale.

[Datto EDR] Add a note to an object in Datto EDR. Purely additive — it records text against the object and changes nothing else, which makes it the safe way to leave an audit trail of what an investigation concluded. Attach it with relatedId: a SHA1 for a file, an object id for anything else.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object, for example {"relatedId":"<object id or file sha1>","comment":"Confirmed false positive - vendor updater."}.

[Datto EDR] Create a triage flag. Additive — it adds a label to the palette and changes nothing that already exists. Note that a flag's weight influences Datto EDR's scoring once analysts start applying it.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object, for example {"name":"Approved vendor tool","color":"green","weight":-5}.

[Datto EDR] Delete a triage flag. Findings that carried it lose that label and its scoring weight, so a flag underpinning a tuning decision should be retired rather than deleted.

ParamTypeRequiredDefaultDescription
flagIdstringyesThe flag id, from dattoedr_list_flags. A GUID.

[Datto EDR] Get one dwell-time record by its own id, from dattoedr_list_file_dwell_times. The record id here is a GUID; the file it describes is identified by a SHA1 in its fileRepId field.

ParamTypeRequiredDefaultDescription
dwellTimeIdstringyesThe dwell-time record id, from dattoedr_list_file_dwell_times. A GUID, not the file's hash.

[Datto EDR] Look up a file's reputation by its SHA1 hash — Datto EDR's verdict on whether that exact binary is known good, unknown or malicious. The direct answer to 'is this hash bad'. Note the identifier: this one takes a 40-character SHA1 hash, not the GUIDs the rest of the connector uses. To find out how long the file has been in the estate, pair it with dattoedr_list_file_dwell_times.

ParamTypeRequiredDefaultDescription
sha1stringyesThe file's SHA1 hash — 40 hexadecimal characters. Not a GUID, and not an MD5 or SHA256.
ParamTypeRequiredDefaultDescription
flagIdstringyesThe flag id, from dattoedr_list_flags. A GUID.

[Datto EDR] List the notes analysts have left on objects — the running commentary on an investigation. Filter on relatedId to see the notes for one object; note that relatedId is a SHA1 when the note is attached to a file and a GUID when it is attached to anything else.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'createdOn DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"relatedId":"<object id or file sha1>"}.

[Datto EDR] List how long files have been present in the estate — first seen, last seen, and on how many machines. Dwell time is the question that turns a detection into an incident scope: a bad file first seen this morning is contained, and one first seen eight months ago is not. Filter on fileRepId, which is a SHA1 hash.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. Datto EDR's maximum is 1000; values above it are clamped.
orderstringnonullSort expression, for example 'firstSeenOn ASC' to surface the longest-resident files.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"fileRepId":"<40-character sha1>"}.
ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'weight DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

[Datto EDR] REPLACE a triage flag wholesale. This is a replace, not an update: every field you leave out of the body is cleared, not preserved. Read the flag first with dattoedr_get_flag and send back the complete object with your changes applied. Changing a flag's weight also changes how everything already carrying it is scored.

ParamTypeRequiredDefaultDescription
bodystringyesThe COMPLETE flag object as JSON. Anything omitted is cleared — start from dattoedr_get_flag rather than sending only the fields you want to change.
flagIdstringyesThe flag id, from dattoedr_list_flags. A GUID.

Vulnerabilities & Compliance

ToolPlanAccessSummary
dattoedr_get_cveFreeRead-onlyGet the detail of one CVE — the detection rules that cover it, its weakness classifications and its references.
dattoedr_list_application_advisoriesFreeRead-onlyList the advisories linking installed applications to known CVEs — the bridge between 'what software is on this estate' and 'which of it is vulnerable'.
dattoedr_list_compliance_result_itemsFreeRead-onlyList the individual checks inside compliance results — which control passed, which failed, and why.
dattoedr_list_compliance_resultsFreeRead-onlyList compliance scan results — one row per machine per compliance run, with its overall outcome.

[Datto EDR] Get the detail of one CVE — the detection rules that cover it, its weakness classifications and its references. Take the CVE id from dattoedr_list_application_advisories.

ParamTypeRequiredDefaultDescription
cveIdstringyesThe CVE identifier, for example CVE-2026-1234.

[Datto EDR] List the advisories linking installed applications to known CVEs — the bridge between 'what software is on this estate' and 'which of it is vulnerable'. Good vCIO and quarterly-review material. Pair it with dattoedr_list_application_instances to find which machines are affected, and dattoedr_get_cve for the detail of a specific vulnerability.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'applicationId ASC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"cveId":"CVE-2026-1234"}.

[Datto EDR] List the individual checks inside compliance results — which control passed, which failed, and why. Filter on complianceResultId to scope to one machine's run, and on passed to list only the failures, which is the list a remediation plan is built from.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'name ASC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"complianceResultId":"<result id>","passed":false}.

[Datto EDR] List compliance scan results — one row per machine per compliance run, with its overall outcome. For the individual checks beneath a result use dattoedr_list_compliance_result_items.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'createdOn DESC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

Detection Rules & Extensions

ToolPlanAccessSummary
dattoedr_create_extensionProDestructiveImport or create an extension — a script Datto EDR will execute on customer endpoints.
dattoedr_create_extension_globalProDestructiveCreate a global variable that extensions read at run time.
dattoedr_create_ruleProWriteCreate a detection rule.
dattoedr_delete_extensionProDestructiveDelete an extension.
dattoedr_delete_ruleProDestructiveDelete a detection rule.
dattoedr_get_extensionFreeRead-onlyGet one extension by id, from dattoedr_list_extensions.
dattoedr_get_extension_latest_versionFreeRead-onlyGet an extension's CURRENT SCRIPT and its checksum.
dattoedr_get_ruleFreeRead-onlyGet one detection rule by id, from dattoedr_list_rules.
dattoedr_get_rule_latest_versionFreeRead-onlyGet a detection rule's CURRENT BODY and its checksum.
dattoedr_list_extension_globalsFreeRead-onlyList the global variables extensions read at run time — the shared configuration values that decide where an extension writes evidence, which endpoints it treats as exceptions, and so on.
dattoedr_list_extensionsFreeRead-onlyList the extensions loaded in this instance — both the collection scripts that gather extra data during a scan and the response scripts that act on an endpoint.
dattoedr_list_rulesFreeRead-onlyList the detection rules on this instance, with their names and current state.
dattoedr_publish_extension_versionProDestructivePublish a new version of an existing extension — new code that will execute on customer endpoints from the next run onward.
dattoedr_publish_rule_versionProWritePublish a new version of an existing detection rule.

[Datto EDR] Import or create an extension — a script Datto EDR will execute on customer endpoints. This is the highest-risk operation on the connector: the script can do whatever its author wrote, on any machine it is later run against, and it is not marked destructive for its verb but for what it makes possible afterwards. Only import scripts you have read and trust, and review them in the Datto EDR interface rather than through an agent wherever you can.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object carrying the extension's name, type and script body.

[Datto EDR] Create a global variable that extensions read at run time. Destructive because of what the value does rather than what the write does: extensions consume these while executing on customer endpoints, so a variable naming a storage destination or an exception list changes the behavior of code running on live machines.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object, for example {"name":"EvidenceBucket","value":"s3://contoso-ir"}.

[Datto EDR] Create a detection rule. Additive and versioned — nothing existing is changed and no code runs on an endpoint, which is why this is not marked destructive. It does change what Datto EDR alerts on from now on, so a rule that matches too broadly produces noise across every customer on the instance. Test the logic against a narrow scope first.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object describing the rule, including its name and body.

[Datto EDR] Delete an extension. Anything that relied on it stops working — including the response actions, which resolve their extension by name at dispatch time, so deleting the isolation extension breaks dattoedr_isolate_host for this instance. Check what uses it before removing it.

ParamTypeRequiredDefaultDescription
extensionIdstringyesThe extension id, from dattoedr_list_extensions. A GUID.

[Datto EDR] Delete a detection rule. Datto EDR stops detecting whatever the rule covered, across every machine, from that moment — this REMOVES SECURITY COVERAGE and the gap is silent. Prefer disabling a noisy rule or publishing a narrower version over deleting it.

ParamTypeRequiredDefaultDescription
ruleIdstringyesThe rule id, from dattoedr_list_rules. A GUID.

[Datto EDR] Get one extension by id, from dattoedr_list_extensions. Returns its record; for the script itself use dattoedr_get_extension_latest_version.

ParamTypeRequiredDefaultDescription
extensionIdstringyesThe extension id, from dattoedr_list_extensions. A GUID.

[Datto EDR] Get an extension's CURRENT SCRIPT and its checksum. Read this before running an extension with dattoedr_run_extension — an extension is code that executes on a customer's endpoint, and this is the only way to see what it will do.

ParamTypeRequiredDefaultDescription
extensionIdstringyesThe extension id, from dattoedr_list_extensions. A GUID.

[Datto EDR] Get one detection rule by id, from dattoedr_list_rules. Returns the rule's record; for its current body and checksum use dattoedr_get_rule_latest_version.

ParamTypeRequiredDefaultDescription
ruleIdstringyesThe rule id, from dattoedr_list_rules. A GUID.

[Datto EDR] Get a detection rule's CURRENT BODY and its checksum. The body is not carried on the rule's own record, so this is the only way to read what a rule actually matches on. Read this before publishing a new version — it is the version you are about to supersede.

ParamTypeRequiredDefaultDescription
ruleIdstringyesThe rule id, from dattoedr_list_rules. A GUID.
ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'name ASC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

[Datto EDR] List the extensions loaded in this instance — both the collection scripts that gather extra data during a scan and the response scripts that act on an endpoint. USE THIS to find the exact extension name the response tools need, particularly dattoedr_collect_evidence and dattoedr_recover_files, which take the name as an argument.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return, up to 1000.
orderstringnonullSort expression, for example 'name ASC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax, for example {"name":{"ilike":"%isolation%"}}.

[Datto EDR] List the detection rules on this instance, with their names and current state. The rule BODY is not on these rows — read it with dattoedr_get_rule_latest_version. Start here when tuning noisy alerts: find the rule an alert's sourceType points at, then read its body before changing anything.

ParamTypeRequiredDefaultDescription
limitintegernonullMaximum records to return. Datto EDR's maximum is 1000; values above it are clamped.
orderstringnonullSort expression, for example 'name ASC'.
skipintegernonullRecords to skip before the first returned row.
wherestringnonullFilter as a JSON object in LoopBack where syntax.

[Datto EDR] Publish a new version of an existing extension — new code that will execute on customer endpoints from the next run onward. Same risk as creating one: anything that runs the extension after this point runs YOUR version. Read the current script with dattoedr_get_extension_latest_version first.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object carrying the new script version.
extensionIdstringyesThe extension id, from dattoedr_list_extensions. A GUID.

[Datto EDR] Publish a new version of an existing detection rule. Not destructive because Datto EDR keeps every prior version and nothing is overwritten — but the new version takes effect immediately, so read the current one with dattoedr_get_rule_latest_version first and know what you are replacing in practice.

ParamTypeRequiredDefaultDescription
bodystringyesRequest body as a JSON object carrying the new rule version.
ruleIdstringyesThe rule id, from dattoedr_list_rules. A GUID.